首页 > 最新文献

Proceedings of the ... ACM symposium on access control models and technologies. ACM Symposium on Access Control Models and Technologies最新文献

英文 中文
Game theoretic analysis of multiparty access control in online social networks 在线社交网络中多方访问控制的博弈论分析
Hongxin Hu, Gail-Joon Ahn, Ziming Zhao, Dejun Yang
Existing online social networks (OSNs) only allow a single user to restrict access to her/his data but cannot provide any mechanism to enforce privacy concerns over data associated with multiple users. This situation leaves privacy conflicts largely unresolved and leads to the potential disclosure of users' sensitive information. To address such an issue, a MultiParty Access Control (MPAC) model was recently proposed, including a systematic approach to identify and resolve privacy conflicts for collaborative data sharing in OSNs. In this paper, we take another step to further study the problem of analyzing the strategic behavior of rational controllers in multiparty access control, where each controller aims to maximize her/his own benefit by adjusting her/his privacy setting in collaborative data sharing in OSNs. We first formulate this problem as a multiparty control game and show the existence of unique Nash Equilibrium (NE) which is critical because at an NE, no controller has any incentive to change her/his privacy setting. We then present algorithms to compute the NE and prove that the system can converge to the NE in only a few iterations. A numerical analysis is also provided for different scenarios that illustrate the interplay of controllers in the multiparty control game. In addition, we conduct user studies of the multiparty control game to explore the gap between game theoretic approaches and real human behaviors.
现有的在线社交网络(OSNs)只允许单个用户限制对他/她的数据的访问,但不能提供任何机制来强制对与多个用户关联的数据进行隐私保护。这种情况使得隐私冲突在很大程度上得不到解决,并可能导致用户敏感信息的泄露。为了解决这一问题,最近提出了一种多方访问控制(MPAC)模型,其中包括一种系统的方法来识别和解决osn中协作数据共享的隐私冲突。在本文中,我们进一步研究了多方访问控制中理性控制器的策略行为分析问题,其中每个控制器的目标是通过调整自己的隐私设置来最大化自己在osn中协同数据共享中的利益。我们首先将这个问题描述为一个多方控制博弈,并展示了唯一纳什均衡(NE)的存在,这是至关重要的,因为在NE中,没有控制器有任何动机改变她/他的隐私设置。然后,我们提出了计算网元的算法,并证明系统可以在几次迭代中收敛到网元。数值分析还提供了不同的场景,说明在多方控制博弈的相互作用的控制器。此外,我们进行了多方控制博弈的用户研究,以探索博弈论方法与真实人类行为之间的差距。
{"title":"Game theoretic analysis of multiparty access control in online social networks","authors":"Hongxin Hu, Gail-Joon Ahn, Ziming Zhao, Dejun Yang","doi":"10.1145/2613087.2613097","DOIUrl":"https://doi.org/10.1145/2613087.2613097","url":null,"abstract":"Existing online social networks (OSNs) only allow a single user to restrict access to her/his data but cannot provide any mechanism to enforce privacy concerns over data associated with multiple users. This situation leaves privacy conflicts largely unresolved and leads to the potential disclosure of users' sensitive information. To address such an issue, a MultiParty Access Control (MPAC) model was recently proposed, including a systematic approach to identify and resolve privacy conflicts for collaborative data sharing in OSNs. In this paper, we take another step to further study the problem of analyzing the strategic behavior of rational controllers in multiparty access control, where each controller aims to maximize her/his own benefit by adjusting her/his privacy setting in collaborative data sharing in OSNs. We first formulate this problem as a multiparty control game and show the existence of unique Nash Equilibrium (NE) which is critical because at an NE, no controller has any incentive to change her/his privacy setting. We then present algorithms to compute the NE and prove that the system can converge to the NE in only a few iterations. A numerical analysis is also provided for different scenarios that illustrate the interplay of controllers in the multiparty control game. In addition, we conduct user studies of the multiparty control game to explore the gap between game theoretic approaches and real human behaviors.","PeriodicalId":74509,"journal":{"name":"Proceedings of the ... ACM symposium on access control models and technologies. ACM Symposium on Access Control Models and Technologies","volume":"39 1","pages":"93-102"},"PeriodicalIF":0.0,"publicationDate":"2014-06-25","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"87569835","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 55
Access control models for geo-social computing systems 地理社会计算系统的访问控制模型
Ebrahim Tarameshloo, Philip W. L. Fong
A Geo-Social Computing System (GSCS) allows users to declare their current locations, and uses these declared locations to make authorization decisions. Recent years have seen the emergence of a new generation of social computing systems that are GSCSs. This paper proposes a protection model for GSCSs. The protection system tracks the current locations of users and a knowledge base of primitive spatial relations between locations. Access control policies can be formulated by the composition of primitive spatial relations. The model is extended to account for Geo-Social Network Systems (GSNSs), which track both a spatial knowledge base and a social network. A policy language for GSNSs is proposed for specifying policies that combine both social and spatial constraints.
地理社会计算系统(GSCS)允许用户声明他们当前的位置,并使用这些声明的位置做出授权决策。近年来出现了新一代的社会计算系统,即gscs。本文提出了一种gscs的保护模型。该保护系统跟踪用户的当前位置和位置之间原始空间关系的知识库。访问控制策略可以通过组合原语空间关系来制定。该模型扩展到地理社会网络系统(GSNSs),它跟踪空间知识库和社会网络。提出了一种用于GSNSs的策略语言,用于指定结合了社会约束和空间约束的策略。
{"title":"Access control models for geo-social computing systems","authors":"Ebrahim Tarameshloo, Philip W. L. Fong","doi":"10.1145/2613087.2613098","DOIUrl":"https://doi.org/10.1145/2613087.2613098","url":null,"abstract":"A Geo-Social Computing System (GSCS) allows users to declare their current locations, and uses these declared locations to make authorization decisions. Recent years have seen the emergence of a new generation of social computing systems that are GSCSs. This paper proposes a protection model for GSCSs. The protection system tracks the current locations of users and a knowledge base of primitive spatial relations between locations. Access control policies can be formulated by the composition of primitive spatial relations. The model is extended to account for Geo-Social Network Systems (GSNSs), which track both a spatial knowledge base and a social network. A policy language for GSNSs is proposed for specifying policies that combine both social and spatial constraints.","PeriodicalId":74509,"journal":{"name":"Proceedings of the ... ACM symposium on access control models and technologies. ACM Symposium on Access Control Models and Technologies","volume":"44 1","pages":"115-126"},"PeriodicalIF":0.0,"publicationDate":"2014-06-25","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"89635219","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 19
A system for risk awareness during role mining 角色挖掘过程中的风险意识系统
Sharmin Ahmed, Sylvia L. Osborn
This paper demonstrates a proof-of-concept prototype that is able to automatically and effectively detect and report different types of risk factors during the process of role mining. A role mining platform is embedded within the tool so that different role-mining algorithms can be used. Once roles are generated, a further analysis is done to detect risk presented by the roles output. To the best of our knowledge there is no such system that effectively detects risk factors and mines roles at the same time. The tool is easy to use, flexible and effective in automatically detecting risk. It can be useful for data analysts and role engineers.
本文展示了一个概念验证原型,该原型能够在角色挖掘过程中自动有效地检测和报告不同类型的风险因素。该工具中嵌入了角色挖掘平台,因此可以使用不同的角色挖掘算法。一旦生成了角色,就会进行进一步的分析,以检测角色输出所带来的风险。据我们所知,目前还没有这样的系统能够同时有效地探测风险因素和地雷的作用。该工具具有使用方便、灵活、有效的风险自动检测功能。它对数据分析师和角色工程师很有用。
{"title":"A system for risk awareness during role mining","authors":"Sharmin Ahmed, Sylvia L. Osborn","doi":"10.1145/2613087.2613095","DOIUrl":"https://doi.org/10.1145/2613087.2613095","url":null,"abstract":"This paper demonstrates a proof-of-concept prototype that is able to automatically and effectively detect and report different types of risk factors during the process of role mining. A role mining platform is embedded within the tool so that different role-mining algorithms can be used. Once roles are generated, a further analysis is done to detect risk presented by the roles output. To the best of our knowledge there is no such system that effectively detects risk factors and mines roles at the same time. The tool is easy to use, flexible and effective in automatically detecting risk. It can be useful for data analysts and role engineers.","PeriodicalId":74509,"journal":{"name":"Proceedings of the ... ACM symposium on access control models and technologies. ACM Symposium on Access Control Models and Technologies","volume":"12 1","pages":"181-184"},"PeriodicalIF":0.0,"publicationDate":"2014-06-25","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"78345938","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 5
Scalable and precise automated analysis of administrative temporal role-based access control 对基于角色的临时管理访问控制进行可扩展和精确的自动化分析
Silvio Ranise, A. Truong, A. Armando
Extensions of Role-Based Access Control (RBAC) policies taking into account contextual information (such as time and space) are increasingly being adopted in real-world applications. Their administration is complex since they must satisfy rapidly evolving needs. For this reason, automated techniques to identify unsafe sequences of administrative actions (i.e. actions generating policies by which a user can acquire permissions that may compromise some security goals) are fundamental tools in the administrator's tool-kit. In this paper, we propose a precise and scalable automated analysis technique for the safety of administrative temporal RBAC policies. Our approach is to translate safety problems for this kind of policy to (decidable) reachability problems of a certain class of symbolic transition systems. The correctness of the translation allows us to design a precise analysis technique for the safety of administrative RBAC policies with a finite but unknown number of users. For scalability, we present a heuristics that allows us to reduce the set of administrative actions without losing the precision of the analysis. An extensive experimental analysis confirms the scalability and precision of the approach also in comparison with a recent analysis technique developed for the same class of temporal RBAC policies.
考虑到上下文信息(如时间和空间)的基于角色的访问控制(RBAC)策略的扩展在实际应用程序中被越来越多地采用。它们的管理是复杂的,因为它们必须满足快速变化的需求。出于这个原因,用于识别不安全管理操作序列的自动化技术(例如,生成策略的操作,用户可以通过这些策略获得可能危及某些安全目标的权限)是管理员工具包中的基本工具。在本文中,我们提出了一种精确和可扩展的自动化分析技术,用于管理临时RBAC策略的安全性。我们的方法是将这类策略的安全问题转化为一类符号转换系统的(可决定的)可达性问题。翻译的正确性使我们能够设计一种精确的分析技术,用于具有有限但未知数量的用户的管理RBAC策略的安全性。对于可伸缩性,我们提出了一种启发式方法,它允许我们在不失去分析精度的情况下减少管理操作集。广泛的实验分析证实了该方法的可扩展性和精确性,并与最近为同一类时间RBAC策略开发的分析技术进行了比较。
{"title":"Scalable and precise automated analysis of administrative temporal role-based access control","authors":"Silvio Ranise, A. Truong, A. Armando","doi":"10.1145/2613087.2613102","DOIUrl":"https://doi.org/10.1145/2613087.2613102","url":null,"abstract":"Extensions of Role-Based Access Control (RBAC) policies taking into account contextual information (such as time and space) are increasingly being adopted in real-world applications. Their administration is complex since they must satisfy rapidly evolving needs. For this reason, automated techniques to identify unsafe sequences of administrative actions (i.e. actions generating policies by which a user can acquire permissions that may compromise some security goals) are fundamental tools in the administrator's tool-kit. In this paper, we propose a precise and scalable automated analysis technique for the safety of administrative temporal RBAC policies. Our approach is to translate safety problems for this kind of policy to (decidable) reachability problems of a certain class of symbolic transition systems. The correctness of the translation allows us to design a precise analysis technique for the safety of administrative RBAC policies with a finite but unknown number of users. For scalability, we present a heuristics that allows us to reduce the set of administrative actions without losing the precision of the analysis. An extensive experimental analysis confirms the scalability and precision of the approach also in comparison with a recent analysis technique developed for the same class of temporal RBAC policies.","PeriodicalId":74509,"journal":{"name":"Proceedings of the ... ACM symposium on access control models and technologies. ACM Symposium on Access Control Models and Technologies","volume":"1 1","pages":"103-114"},"PeriodicalIF":0.0,"publicationDate":"2014-06-25","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"89737572","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 25
Anomaly detection and visualization in generative RBAC models 生成式RBAC模型中的异常检测与可视化
Maria Leitner, S. Rinderle-Ma
With the wide use of Role-based Access Control (RBAC), the need for monitoring, evaluation, and verification of RBAC implementations (e.g., to evaluate ex post which users acting in which roles were authorized to execute permissions) is evident. In this paper, we aim at detecting and identifying anomalies that originate from insiders such as the infringement of rights or irregular activities. To do that, we compare prescriptive (original) RBAC models (i.e. how the RBAC model is expected to work) with generative (current-state) RBAC models (i.e. the actual accesses represented by an RBAC model obtained with mining techniques). For this we present different similarity measures for RBAC models and their entities. We also provide techniques for visualizing anomalies within RBAC models based on difference graphs. This can be used for the alignment of RBAC models such as for policy updates or reconciliation. The effectiveness of the approach is evaluated based on a prototypical implementation and an experiment.
随着基于角色的访问控制(Role-based Access Control, RBAC)的广泛使用,监视、评估和验证RBAC实现(例如,事后评估哪些用户在哪些角色中被授权执行权限)的需求是显而易见的。在本文中,我们的目标是检测和识别源自内部人员的异常,例如侵权或违规活动。为此,我们比较了规定性(原始)RBAC模型(即RBAC模型的预期工作方式)与生成式(当前状态)RBAC模型(即通过挖掘技术获得的RBAC模型所表示的实际访问)。为此,我们提出了不同的RBAC模型及其实体的相似性度量。我们还提供了基于差分图的RBAC模型中的异常可视化技术。这可以用于RBAC模型的对齐,例如策略更新或调节。通过一个原型实现和一个实验,对该方法的有效性进行了评价。
{"title":"Anomaly detection and visualization in generative RBAC models","authors":"Maria Leitner, S. Rinderle-Ma","doi":"10.1145/2613087.2613105","DOIUrl":"https://doi.org/10.1145/2613087.2613105","url":null,"abstract":"With the wide use of Role-based Access Control (RBAC), the need for monitoring, evaluation, and verification of RBAC implementations (e.g., to evaluate ex post which users acting in which roles were authorized to execute permissions) is evident. In this paper, we aim at detecting and identifying anomalies that originate from insiders such as the infringement of rights or irregular activities. To do that, we compare prescriptive (original) RBAC models (i.e. how the RBAC model is expected to work) with generative (current-state) RBAC models (i.e. the actual accesses represented by an RBAC model obtained with mining techniques). For this we present different similarity measures for RBAC models and their entities. We also provide techniques for visualizing anomalies within RBAC models based on difference graphs. This can be used for the alignment of RBAC models such as for policy updates or reconciliation. The effectiveness of the approach is evaluated based on a prototypical implementation and an experiment.","PeriodicalId":74509,"journal":{"name":"Proceedings of the ... ACM symposium on access control models and technologies. ACM Symposium on Access Control Models and Technologies","volume":"19 1","pages":"41-52"},"PeriodicalIF":0.0,"publicationDate":"2014-06-25","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"72725880","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 3
Re-thinking networked privacy, security, identity and access control in our surveillance states 在我们的监控状态下重新思考网络隐私、安全、身份和访问控制
A. Clement
Mass surveillance activities by the security agencies of the Five Eyes countries (e.g. NSA, CSEC, etc) pose a significant challenge to those who care about the privacy, security and other democratic rights related to our burgeoning digitally mediated communications. The on-going media coverage of the Snowden documents has brought unprecedented attention to longstanding concerns about whether and how individuals can exercise effective control over their personal information as we increasingly lead our lives on-line. The revelations are also undermining comfortable assumptions about the institutions and infrastructures we depend on for the efficient and equitable functioning of a democratic society. We've seen agencies mandated to protect our networks compromise once trusted security standards, and secretly hoard vulnerabilities for later exploitation rather than fix them. We are witnesses to government and their corporate partners secretly accessing massive amounts of our data, and grudgingly acknowledge their activities only when forced to by whistleblowers. How can we restore trust in the organizations we interact with and hand our personal data to on a daily basis? How can we require them to be more open, transparent and accountable? What are the technically viable options that can help achieve the reliable protections that many regard as fundamental and wish they could take for granted? Drawing on recent research, this talk will review some of the key surveillance challenges we face in the areas of internet routing and identity authentication. The IXmaps.ca project provides a mapping tool for visualizing the routes data packets take across the internet backbone, and in particular where one's own traffic may be subject to NSA interception at key internet routing choke points. It further documents patterns of "boomerang routing", whereby domestic Canadian traffic is often routed via the US, exposing it to foreign surveillance, and compares the data privacy transparency of the various carriers which handle this traffic en route.
“五眼联盟”国家安全机构(如NSA、CSEC等)的大规模监控活动,对那些关心隐私、安全和其他与我们迅速发展的数字媒介通信相关的民主权利的人构成了重大挑战。媒体对斯诺登文件的持续报道,让人们前所未有地关注到一个长期存在的问题:随着我们越来越多地生活在网络上,个人能否以及如何对自己的个人信息进行有效控制。这些披露也在破坏我们对民主社会高效、公平运转所依赖的制度和基础设施的舒适假设。我们看到,为了保护我们的网络,政府机构不得不妥协曾经值得信赖的安全标准,秘密地囤积漏洞以供日后利用,而不是修复它们。我们目睹了政府及其企业合作伙伴秘密获取我们的大量数据,只有在举报人的逼迫下才勉强承认他们的活动。我们如何才能恢复对我们每天与之互动并向其提供个人数据的组织的信任?我们怎样才能要求他们更加开放、透明和负责?哪些技术上可行的选择可以帮助实现许多人认为是基本的、并希望他们可以理所当然的可靠保护?根据最近的研究,本次演讲将回顾我们在互联网路由和身份认证领域面临的一些关键监控挑战。IXmaps。ca项目提供了一个映射工具,用于可视化数据包通过互联网主干的路由,特别是在一个人自己的流量可能受到NSA在关键互联网路由阻塞点拦截的情况下。它进一步记录了“回旋路由”模式,即加拿大国内流量通常经由美国路由,使其暴露于外国监控之下,并比较了处理这些流量的不同运营商的数据隐私透明度。
{"title":"Re-thinking networked privacy, security, identity and access control in our surveillance states","authors":"A. Clement","doi":"10.1145/2613087.2613089","DOIUrl":"https://doi.org/10.1145/2613087.2613089","url":null,"abstract":"Mass surveillance activities by the security agencies of the Five Eyes countries (e.g. NSA, CSEC, etc) pose a significant challenge to those who care about the privacy, security and other democratic rights related to our burgeoning digitally mediated communications. The on-going media coverage of the Snowden documents has brought unprecedented attention to longstanding concerns about whether and how individuals can exercise effective control over their personal information as we increasingly lead our lives on-line. The revelations are also undermining comfortable assumptions about the institutions and infrastructures we depend on for the efficient and equitable functioning of a democratic society. We've seen agencies mandated to protect our networks compromise once trusted security standards, and secretly hoard vulnerabilities for later exploitation rather than fix them. We are witnesses to government and their corporate partners secretly accessing massive amounts of our data, and grudgingly acknowledge their activities only when forced to by whistleblowers. How can we restore trust in the organizations we interact with and hand our personal data to on a daily basis? How can we require them to be more open, transparent and accountable? What are the technically viable options that can help achieve the reliable protections that many regard as fundamental and wish they could take for granted?\u0000 Drawing on recent research, this talk will review some of the key surveillance challenges we face in the areas of internet routing and identity authentication. The IXmaps.ca project provides a mapping tool for visualizing the routes data packets take across the internet backbone, and in particular where one's own traffic may be subject to NSA interception at key internet routing choke points. It further documents patterns of \"boomerang routing\", whereby domestic Canadian traffic is often routed via the US, exposing it to foreign surveillance, and compares the data privacy transparency of the various carriers which handle this traffic en route.","PeriodicalId":74509,"journal":{"name":"Proceedings of the ... ACM symposium on access control models and technologies. ACM Symposium on Access Control Models and Technologies","volume":"52 1","pages":"185-186"},"PeriodicalIF":0.0,"publicationDate":"2014-06-25","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"82257094","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 1
Sorting out role based access control 整理基于角色的访问控制
W. Kuijper, Victor Ermolaev
Role-based access control (RBAC) is a popular framework for modelling access control rules. In this paper we identify a fragment of RBAC called bi-sorted role based access control (RBAC). We start from the observation that "classic" RBAC blends together subject management aspects and permission management aspects into a single object of indirection: a role. We posit there is merit in distinguishing these administrative perspectives and consequently introducing two distinct objects of indirection: the proper role (which applies solely to subjects) and the demarcation (which applies solely to permissions). We then identify a third administrative perspective called access management where the two are linked up. In this way we enhance organisational scalability by decoupling the tasks of maintaining abstractions over the set of subjects (assignment of subjects into proper roles), maintaining abstractions over the set of permissions (assignment of permissions into demarcations), and maintaining abstract access control policy (granting proper roles access to demarcations). Moreover, the latter conceptual refinement naturally leads us to the introduction of negative roles (and, dually, negative demarcations). The relevance of the four-sorted extension called polarized, bi-sorted role based access control (RpmBAC), in a semantic sense, is further supported by the existence of Galois connections between sets of subjects and permissions and between positive and negative roles.
基于角色的访问控制(RBAC)是一种流行的访问控制规则建模框架。在本文中,我们确定了RBAC的一个片段,称为基于双排序角色的访问控制(RBAC)。我们从观察到“经典”RBAC将主题管理方面和权限管理方面混合到一个间接对象中:角色。我们认为,区分这些管理视角并因此引入两个不同的间接对象是有价值的:适当的角色(仅适用于主体)和界限(仅适用于许可)。然后,我们确定称为访问管理的第三个管理透视图,其中将两者联系在一起。通过这种方式,我们通过解耦维护主题集上的抽象(将主题分配到适当的角色中)、维护权限集上的抽象(将权限分配到界限中)和维护抽象访问控制策略(授予适当的角色对界限的访问权)的任务来增强组织的可伸缩性。此外,后一种概念的细化自然会引导我们引入消极角色(以及双重的消极界限)。在语义意义上,四排序扩展的相关性被称为极化、双排序的基于角色的访问控制(RpmBAC),在主题和权限集之间以及积极和消极角色之间存在的Galois连接进一步支持了这种关联性。
{"title":"Sorting out role based access control","authors":"W. Kuijper, Victor Ermolaev","doi":"10.1145/2613087.2613101","DOIUrl":"https://doi.org/10.1145/2613087.2613101","url":null,"abstract":"Role-based access control (RBAC) is a popular framework for modelling access control rules. In this paper we identify a fragment of RBAC called bi-sorted role based access control (RBAC). We start from the observation that \"classic\" RBAC blends together subject management aspects and permission management aspects into a single object of indirection: a role. We posit there is merit in distinguishing these administrative perspectives and consequently introducing two distinct objects of indirection: the proper role (which applies solely to subjects) and the demarcation (which applies solely to permissions). We then identify a third administrative perspective called access management where the two are linked up. In this way we enhance organisational scalability by decoupling the tasks of maintaining abstractions over the set of subjects (assignment of subjects into proper roles), maintaining abstractions over the set of permissions (assignment of permissions into demarcations), and maintaining abstract access control policy (granting proper roles access to demarcations). Moreover, the latter conceptual refinement naturally leads us to the introduction of negative roles (and, dually, negative demarcations). The relevance of the four-sorted extension called polarized, bi-sorted role based access control (RpmBAC), in a semantic sense, is further supported by the existence of Galois connections between sets of subjects and permissions and between positive and negative roles.","PeriodicalId":74509,"journal":{"name":"Proceedings of the ... ACM symposium on access control models and technologies. ACM Symposium on Access Control Models and Technologies","volume":"95 1","pages":"63-74"},"PeriodicalIF":0.0,"publicationDate":"2014-06-25","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"79236715","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 12
User-centric identity as a service-architecture for eIDs with selective attribute disclosure 以用户为中心的身份作为具有选择性属性公开的eid的服务体系结构
Daniel Slamanig, Klaus Stranacher, Bernd Zwattendorfer
Unique identification and secure authentication of users are essential processes in numerous security-critical areas such as e-Government, e-Banking, or e-Business. Therefore, many countries (particularly in Europe) have implemented national eID solutions within the past years. Such implementations are typically based on smart cards holding some certified collection of citizen attributes and hence follow a client-side and user-centric approach. However, most of the implementations only support all-or-nothing disclosure of citizen attributes and thus do not allow privacy-friendly selective disclosure of attributes. Consequently, the complete identity of the citizen (all attributes) are always revealed to identity providers and/or service providers, respectively. In this paper, we propose a novel user-centric identification and authentication model for eIDs, which supports selective attribute disclosure but only requires minimal changes in the existing eID architecture. In addition, our approach allows service providers to keep their infrastructure nearly untouched. Latter is often an inhibitor for the use of privacy-preserving cryptography like anonymous credentials in such architectures. Furthermore, our model can easily be deployed in the public cloud as we do not require full trust in identity providers. This fully features the Identity as a Service-paradigm while at the same time preserves citizens' privacy. We demonstrate the applicability of our model by adopting to the Austrian eID system to our approach.
用户的唯一标识和安全认证是许多安全关键领域(如电子政务、电子银行或电子商务)的基本流程。因此,许多国家(特别是欧洲国家)在过去几年中实施了国家eID解决方案。此类实现通常基于持有某些经过认证的公民属性集合的智能卡,因此遵循以客户端和用户为中心的方法。然而,大多数实现只支持对公民属性进行全有或全无的披露,因此不允许对属性进行隐私友好的选择性披露。因此,公民的完整身份(所有属性)总是分别显示给身份提供者和/或服务提供者。本文提出了一种新的以用户为中心的eID身份识别和认证模型,该模型支持选择性属性披露,但只需要对现有eID架构进行最小的更改。此外,我们的方法允许服务提供商保持其基础设施几乎不受影响。后者通常是在此类体系结构中使用匿名凭据等保护隐私的加密技术的阻碍。此外,我们的模型可以很容易地部署在公共云中,因为我们不需要完全信任身份提供者。这充分体现了身份即服务范式的特点,同时保护了公民的隐私。我们通过采用奥地利eID系统来证明我们模型的适用性。
{"title":"User-centric identity as a service-architecture for eIDs with selective attribute disclosure","authors":"Daniel Slamanig, Klaus Stranacher, Bernd Zwattendorfer","doi":"10.1145/2613087.2613093","DOIUrl":"https://doi.org/10.1145/2613087.2613093","url":null,"abstract":"Unique identification and secure authentication of users are essential processes in numerous security-critical areas such as e-Government, e-Banking, or e-Business. Therefore, many countries (particularly in Europe) have implemented national eID solutions within the past years. Such implementations are typically based on smart cards holding some certified collection of citizen attributes and hence follow a client-side and user-centric approach. However, most of the implementations only support all-or-nothing disclosure of citizen attributes and thus do not allow privacy-friendly selective disclosure of attributes. Consequently, the complete identity of the citizen (all attributes) are always revealed to identity providers and/or service providers, respectively. In this paper, we propose a novel user-centric identification and authentication model for eIDs, which supports selective attribute disclosure but only requires minimal changes in the existing eID architecture. In addition, our approach allows service providers to keep their infrastructure nearly untouched. Latter is often an inhibitor for the use of privacy-preserving cryptography like anonymous credentials in such architectures. Furthermore, our model can easily be deployed in the public cloud as we do not require full trust in identity providers. This fully features the Identity as a Service-paradigm while at the same time preserves citizens' privacy. We demonstrate the applicability of our model by adopting to the Austrian eID system to our approach.","PeriodicalId":74509,"journal":{"name":"Proceedings of the ... ACM symposium on access control models and technologies. ACM Symposium on Access Control Models and Technologies","volume":"101 1","pages":"153-164"},"PeriodicalIF":0.0,"publicationDate":"2014-06-25","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"74359358","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 15
A bodyguard of lies: the use of honey objects in information security 谎言的保镖:在信息安全中使用蜂蜜对象
A. Juels
Decoy objects, often labeled in computer security with the term honey, are a powerful tool for compromise detection and mitigation. There has been little exploration of overarching theories or set of principles or properties, however. This short paper (and accompanying keynote talk) briefly explore two properties of honey systems, indistinguishability and secrecy. The aim is to illuminate a broad design space that might encompass a wide array of areas in information security, including access control, the main topic of this symposium. Dr. Ari Juels is a roving chief scientist specializing in computer security. He was Chief Scientist of RSA (The Security Division of EMC), Director of RSA Laboratories, and a Distinguished Engineer at EMC, where he worked until September 2013. He joined RSA in 1996 after receiving his Ph.D. in computer science from U.C. Berkeley. His recent areas of interest include "big data" security analytics, cybersecurity, cloud security, user authentication, privacy, medical-device security, biometric security, and RFID / NFC security. As an industry scientist, Dr. Juels has helped incubate innovative new product features and products and advised on the science behind security-industry strategy. He is also a frequent public speaker, and has published highly cited scientific papers on many topics in computer security. In 2004, MIT's Technology Review Magazine named Dr. Juels one of the world's top 100 technology innovators under the age of 35. Computerworld honored him in its "40 Under 40" list of young industry leaders in 2007. He has received other distinctions, but sadly no recent ones acknowledging his youth.
诱饵对象,通常在计算机安全中被标记为“蜂蜜”,是检测和缓解危害的强大工具。然而,对总体理论或一套原则或特性的探索却很少。这篇短文(和伴随的主题演讲)简要地探讨了蜂蜜系统的两个特性,不可区分性和保密性。其目的是阐明一个广泛的设计空间,该空间可能包含信息安全的广泛领域,包括本次研讨会的主要主题访问控制。Ari Juels博士是一名专门研究计算机安全的巡回首席科学家。他曾担任RSA (EMC的安全部门)的首席科学家,RSA实验室的主任,以及EMC的杰出工程师,在那里他一直工作到2013年9月。在加州大学伯克利分校获得计算机科学博士学位后,他于1996年加入RSA。他最近感兴趣的领域包括“大数据”安全分析、网络安全、云安全、用户身份验证、隐私、医疗设备安全、生物识别安全以及RFID / NFC安全。作为一名行业科学家,Juels博士帮助孵化创新的新产品功能和产品,并就安全行业战略背后的科学提供建议。他也是一个经常公开演讲的人,并发表了关于计算机安全的许多主题的高引用的科学论文。2004年,麻省理工学院的技术评论杂志将Juels博士评为35岁以下世界前100名技术创新者之一。2007年,他被《计算机世界》评为“40位40岁以下”的年轻行业领袖。他还获得过其他荣誉,但遗憾的是,最近没有人承认他的年轻。
{"title":"A bodyguard of lies: the use of honey objects in information security","authors":"A. Juels","doi":"10.1145/2613087.2613088","DOIUrl":"https://doi.org/10.1145/2613087.2613088","url":null,"abstract":"Decoy objects, often labeled in computer security with the term honey, are a powerful tool for compromise detection and mitigation. There has been little exploration of overarching theories or set of principles or properties, however. This short paper (and accompanying keynote talk) briefly explore two properties of honey systems, indistinguishability and secrecy. The aim is to illuminate a broad design space that might encompass a wide array of areas in information security, including access control, the main topic of this symposium.\u0000 Dr. Ari Juels is a roving chief scientist specializing in computer security.\u0000 He was Chief Scientist of RSA (The Security Division of EMC), Director of RSA Laboratories, and a Distinguished Engineer at EMC, where he worked until September 2013. He joined RSA in 1996 after receiving his Ph.D. in computer science from U.C. Berkeley.\u0000 His recent areas of interest include \"big data\" security analytics, cybersecurity, cloud security, user authentication, privacy, medical-device security, biometric security, and RFID / NFC security. As an industry scientist, Dr. Juels has helped incubate innovative new product features and products and advised on the science behind security-industry strategy. He is also a frequent public speaker, and has published highly cited scientific papers on many topics in computer security.\u0000 In 2004, MIT's Technology Review Magazine named Dr. Juels one of the world's top 100 technology innovators under the age of 35. Computerworld honored him in its \"40 Under 40\" list of young industry leaders in 2007. He has received other distinctions, but sadly no recent ones acknowledging his youth.","PeriodicalId":74509,"journal":{"name":"Proceedings of the ... ACM symposium on access control models and technologies. ACM Symposium on Access Control Models and Technologies","volume":"76 1","pages":"1-4"},"PeriodicalIF":0.0,"publicationDate":"2014-06-25","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"85561822","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 23
Reduction of access control decisions 减少访问控制决策
C. Morisset, Nicola Zannone
Access control has been proposed as "the" solution to prevent unauthorized accesses to sensitive system resources. Historically, access control models use a two-valued decision set to indicate whether an access should be granted or denied. Many access control models have extended the two-valued decision set to indicate, for instance, whether a policy is applicable to an access query or an error occurred during policy evaluation. Decision sets are often coupled with operators for combining decisions from multiple applicable policies. Although a larger decision set is more expressive, it may be necessary to reduce it to a smaller set in order to simplify the complexity of decision making or enable comparison between access control models. Moreover, some access control mechanisms like XACML~v3 uses more than one decision set. The projection from one decision set to the other may result in a loss of accuracy, which can affect the final access decision. In this paper, we present a formal framework for the analysis and comparison of decision sets centered on the notion of decision reduction. In particular, we introduce the notion of safe reduction, which ensures that a reduction can be performed at any level of policy composition without changing the final decision. We demonstrate the framework by analyzing XACML v3 against the notion of safe reduction. From this analysis, we draw guidelines for the selection of the minimal decision set with respect to a given set of combining operators.
访问控制被认为是防止对敏感系统资源的未经授权访问的“解决方案”。从历史上看,访问控制模型使用一个双值决策集来指示是否应该授予或拒绝访问。许多访问控制模型已经扩展了二值决策集,例如,表明策略是否适用于访问查询或策略评估期间发生的错误。决策集通常与运算符相结合,用于组合来自多个适用策略的决策。尽管更大的决策集更具表现力,但为了简化决策制定的复杂性或支持访问控制模型之间的比较,可能有必要将其缩减为更小的决策集。此外,一些访问控制机制(如XACML~v3)使用多个决策集。从一个决策集到另一个决策集的投影可能会导致准确性的损失,从而影响最终的访问决策。在本文中,我们以决策约简的概念为中心,提出了一个用于分析和比较决策集的形式化框架。特别是,我们引入了安全减量的概念,它确保在不改变最终决策的情况下,可以在任何级别的政策组合中执行减量。我们通过分析XACML v3的安全缩减概念来演示该框架。从这个分析中,我们得出了关于给定组合算子集的最小决策集的选择准则。
{"title":"Reduction of access control decisions","authors":"C. Morisset, Nicola Zannone","doi":"10.1145/2613087.2613106","DOIUrl":"https://doi.org/10.1145/2613087.2613106","url":null,"abstract":"Access control has been proposed as \"the\" solution to prevent unauthorized accesses to sensitive system resources. Historically, access control models use a two-valued decision set to indicate whether an access should be granted or denied. Many access control models have extended the two-valued decision set to indicate, for instance, whether a policy is applicable to an access query or an error occurred during policy evaluation. Decision sets are often coupled with operators for combining decisions from multiple applicable policies. Although a larger decision set is more expressive, it may be necessary to reduce it to a smaller set in order to simplify the complexity of decision making or enable comparison between access control models. Moreover, some access control mechanisms like XACML~v3 uses more than one decision set. The projection from one decision set to the other may result in a loss of accuracy, which can affect the final access decision. In this paper, we present a formal framework for the analysis and comparison of decision sets centered on the notion of decision reduction. In particular, we introduce the notion of safe reduction, which ensures that a reduction can be performed at any level of policy composition without changing the final decision. We demonstrate the framework by analyzing XACML v3 against the notion of safe reduction. From this analysis, we draw guidelines for the selection of the minimal decision set with respect to a given set of combining operators.","PeriodicalId":74509,"journal":{"name":"Proceedings of the ... ACM symposium on access control models and technologies. ACM Symposium on Access Control Models and Technologies","volume":"85 1","pages":"53-62"},"PeriodicalIF":0.0,"publicationDate":"2014-06-25","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"89618321","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 13
期刊
Proceedings of the ... ACM symposium on access control models and technologies. ACM Symposium on Access Control Models and Technologies
全部 Acc. Chem. Res. ACS Applied Bio Materials ACS Appl. Electron. Mater. ACS Appl. Energy Mater. ACS Appl. Mater. Interfaces ACS Appl. Nano Mater. ACS Appl. Polym. Mater. ACS BIOMATER-SCI ENG ACS Catal. ACS Cent. Sci. ACS Chem. Biol. ACS Chemical Health & Safety ACS Chem. Neurosci. ACS Comb. Sci. ACS Earth Space Chem. ACS Energy Lett. ACS Infect. Dis. ACS Macro Lett. ACS Mater. Lett. ACS Med. Chem. Lett. ACS Nano ACS Omega ACS Photonics ACS Sens. ACS Sustainable Chem. Eng. ACS Synth. Biol. Anal. Chem. BIOCHEMISTRY-US Bioconjugate Chem. BIOMACROMOLECULES Chem. Res. Toxicol. Chem. Rev. Chem. Mater. CRYST GROWTH DES ENERG FUEL Environ. Sci. Technol. Environ. Sci. Technol. Lett. Eur. J. Inorg. Chem. IND ENG CHEM RES Inorg. Chem. J. Agric. Food. Chem. J. Chem. Eng. Data J. Chem. Educ. J. Chem. Inf. Model. J. Chem. Theory Comput. J. Med. Chem. J. Nat. Prod. J PROTEOME RES J. Am. Chem. Soc. LANGMUIR MACROMOLECULES Mol. Pharmaceutics Nano Lett. Org. Lett. ORG PROCESS RES DEV ORGANOMETALLICS J. Org. Chem. J. Phys. Chem. J. Phys. Chem. A J. Phys. Chem. B J. Phys. Chem. C J. Phys. Chem. Lett. Analyst Anal. Methods Biomater. Sci. Catal. Sci. Technol. Chem. Commun. Chem. Soc. Rev. CHEM EDUC RES PRACT CRYSTENGCOMM Dalton Trans. Energy Environ. Sci. ENVIRON SCI-NANO ENVIRON SCI-PROC IMP ENVIRON SCI-WAT RES Faraday Discuss. Food Funct. Green Chem. Inorg. Chem. Front. Integr. Biol. J. Anal. At. Spectrom. J. Mater. Chem. A J. Mater. Chem. B J. Mater. Chem. C Lab Chip Mater. Chem. Front. Mater. Horiz. MEDCHEMCOMM Metallomics Mol. Biosyst. Mol. Syst. Des. Eng. Nanoscale Nanoscale Horiz. Nat. Prod. Rep. New J. Chem. Org. Biomol. Chem. Org. Chem. Front. PHOTOCH PHOTOBIO SCI PCCP Polym. Chem.
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
Book学术官方微信
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1